Trust center
Security boundaries you can evaluate
A practical summary of what Veil protects, what the cloud processes, who supports the service and where the product’s limits remain.
Last reviewed: 14 July 2026 · Applies to Veil 1.5
Core security model
Local protection
Detection, masking, encryption and decryption run in the browser. Veil uses AES-GCM with PBKDF2-derived keys for local protected text.
Customer-held passphrases
Personal and Business passphrases are retained locally and are not uploaded, synchronized or recoverable by Goldspire.
Verified browsers
Every Personal or Business browser using cloud features requires mailbox approval. Business administrators can revoke browsers individually.
Cloud data boundaries
- Processed: account email, organization membership, device approval, policy settings, encrypted token/share blobs, billing references, support submissions and optional metadata-only Business events.
- Rejected or excluded: matched plaintext, decrypted content, full message bodies, full prompts and customer-held passphrases.
- Organization events: may include category, severity, host, action, confidence, member and device identifiers, but not the matched value.
- Personal learning: Copilot decisions remain local in Veil 1.5 and are not uploaded to Goldspire.
- Protection updates: validated before use and rejected when authenticity cannot be established.
Detection coverage and limits
Veil looks for high-confidence credentials, payment and banking details, contact information, government and health identifiers, and customer or internal references. Common casing, spacing and separator variations are supported for many structured formats.
- Browser text fields: protection applies when you type, paste or select text in supported Chrome and Edge web fields and editors.
- Global formats: Veil supports all current SWIFT IBAN country lengths and a growing set of national identifiers. It does not claim every identifier, language or country-specific format.
- Not inspected in 1.5: attachment contents, images or scans, audio, native desktop/mobile applications and unsupported custom or canvas-based editors. Supported AI sites can warn or block the file action without reading the file.
- Safety boundary: detection can miss sensitive information or flag a benign lookalike. Veil assists the user; it does not replace judgment or an organization’s other security controls.
View the versioned 1.5 coverage and compatibility catalogue.
Service providers
| Provider | Purpose | Typical data |
|---|---|---|
| Cloudflare | Portal delivery, DNS, TLS and edge security | IP address and request metadata |
| Railway | API hosting and application runtime | Account, organization, policy, support and event metadata processed by the API |
| Supabase | Managed PostgreSQL database | Accounts, approvals, policies, ciphertext, billing references and security metadata |
| Stripe | Subscription checkout and billing | Customer, subscription and payment information; Goldspire does not store full card details |
| Brevo / Resend | Transactional email | Recipient email, verification or invitation content and delivery metadata |
| Anthropic (Goldspire Support AI) | Policy-bound support classification and reply drafting | Submitted support message and safe diagnostic metadata; contact email is excluded from model input where practical |
| OpenAI (optional alternative) | Support classification and reply drafting only when explicitly selected by Goldspire | The same minimized support message and safe diagnostic metadata |
| GitHub | Private source control and release automation | Source code, CI logs and development metadata; production customer content is not intentionally stored there |
Customer-configured SIEM or identity destinations are controlled by the customer and are not Goldspire subprocessors for that independent use.
Default retention
| Data class | Default retention |
|---|---|
| Browser approval tokens | 24 hours or successful approval |
| Revoked or expired join codes | 90 days |
| Revoked browser records | 12 months, unless needed for a security investigation |
| Security-event metadata | 90 days by default |
| Encrypted token/share blobs | Configured expiry or read limit; maximum 90 days unless contractually extended |
| Support tickets | 24 months after closure |
| Operational request metrics | 30 days |
| Database backups | 35 days |
| Billing records | Contract term plus statutory accounting/tax period where required |
Operational security
Release controls
Veil releases pass security, compatibility and customer-journey checks before packaging.
Incident response
Goldspire maintains incident classification, containment, evidence, notification and recovery procedures for Veil operations.
Backup and recovery
Production readiness includes managed backups, restore procedures and recorded recovery exercises.
Compliance posture
Veil includes policy context for GDPR, PCI DSS, HIPAA, SOC 2 and ISO 27001-aligned workflows. These mappings are product guidance; they do not make a customer compliant and do not represent certification of Goldspire or Veil.
Enterprise customers may request the available security and procurement materials from Sales.
Report a vulnerability
Send security reports privately. Include the affected feature, reproduction steps and potential impact. Do not access other users’ data or run disruptive testing.